CVE-2025-32544: WordPress WooCommerce Loyal Customers plugin <= 2.6 - Broken Access Control vulnerability

7.5 CVSS

Description

Missing Authorization vulnerability in The Right Software WooCommerce Loyal Customers allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects WooCommerce Loyal Customers: from n/a through 2.6.

Classification

CVE ID: CVE-2025-32544

CVSS Base Severity: HIGH

CVSS Base Score: 7.5

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Problem Types

CWE-862 Missing Authorization

Affected Products

Vendor: The Right Software

Product: WooCommerce Loyal Customers

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.03% (probability of being exploited)

EPSS Percentile: 7.39% (scored less or equal to compared to others)

EPSS Date: 2025-04-18 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2025-32544
https://patchstack.com/database/wordpress/plugin/woocommerce-loyal-customer/vulnerability/wordpress-woocommerce-loyal-customers-plugin-2-6-broken-access-control-vulnerability?_s_id=cve

Timeline